Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2024-3094
CVE
CVE-2024-3094
View on NVD ↗
Xz: malicious code in distributed source
Exploitation IoCs
2
Package
cacheable-request
Package
keyv
MITRE ATT&CK TTPs
5
T1059.001
PowerShell
Execution
T1071.001
Web Protocols
Command And Control
T1078.004
Cloud Accounts
Defense Evasion
T1090.004
Domain Fronting
Command And Control
T1566
Phishing
Initial Access
Source Articles
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
The article details the ChainDrop npm worm, a self-propagating supply chain attack that infected over 400 npm packages, including popular libraries like keyv and cacheable-request. It leverages malicious preinstall scripts to download an obfuscated payload, steals cloud secrets from CI/CD environments (including GitHub Actions OIDC tokens), backdoors local developer tools such as VS Code, and uses stolen tokens to automatically propagate. The malware maintains persistence through integration with developer tools and uses Ethereum blockchain for dynamic command-and-control infrastructure, highlighting the expanding threat surface in the software development lifecycle.
unit42
Aug 21, 2026